logo

CVE-2025-68670: discovering an RCE vulnerability in xrdp

ID: 13058ccf-afd6-5238-9b3f-5dec37b5114f

STIX ID: report--13058ccf-afd6-5238-9b3f-5dec37b5114f

Feed Name: Securelist by Kaspersky

Threat Score
70/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Denis Skvortsov, Dmitry Shmoylov

...
...

Kaspersky researchers found and responsibly disclosed CVE-2025-68670, a pre-authentication remote code execution vulnerability in xrdp where overly long UTF-16 domain strings are converted to UTF-8 and copied into a 256-byte buffer, enabling stack-based buffer overflow and potential control-flow hijacking; the report includes a PoC, analysis of mitigation (stack canaries), and a timeline showing the issue was patched and backported by xrdp maintainers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.